Repository navigation
Update backdoor-deployment skill to use the in-repo chart - #1795
Merged
Merged
Conversation
The skill targeted the external sibling chart `azuremonitor-containerinsights-for-prod-clusters`, which no longer reflects how CI/CD deploys the agent. Retarget it at the in-repo `charts/azuremonitor-containerinsights` and correct the mechanics that differ, verified by a live backdoor deployment. Chart generation - The chart is template-only (`Chart-template.yaml` / `values-template.yaml`); Helm fails with "Chart.yaml file is missing" until `envsubst` generates them. Document the generation step, matching `.pipelines/helm-deploy-templates/ama-logs-helm-deploy.yaml`. Image tags - Images are assembled as MCR host + `imageRepository` + `:` + tag, so tags must be bare and the ciprod/cidev switch is a separate `imageRepository` value. The old `cidev:<tag>` form rendered an invalid reference. - Warn that an empty tag silently falls back to the hardcoded `3.1.34` in `get.addonImageTag`, which would otherwise compare prod against prod, and require reading the deployed image back before collecting data. Inputs - Reduce required inputs to branch name and cluster resource ID. - Resolve the production image from `ReleaseNotes.md` instead of hardcoding a tag that goes stale. - Resolve the workspace from the cluster's ContainerInsightsExtension DCR, including a bootstrap path that enables the addon once when no DCR exists yet. Clusters onboarded without an explicit workspace land in a regional default whose name is unrelated to the cluster. Deployment - Document the full CI/CD override set, including `accessTokenSecretName=aad-msi-auth-token`, which MSI clusters need in place of the chart's legacy workspace-key default. - Note that `--server-side` / `--force-conflicts` are Helm 4 flags and fail on Helm 3. - Record that disabling the managed addon is mandatory, since installing over it fails with a Helm ownership error, and that cleanup must restore the addon to its original state. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4fc0848a-8d3a-4c44-a69e-fd3bfe11ca50
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). 2 pipeline(s) were filtered out due to trigger conditions. |
zanejohnson-azure
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
backdoor-deploymentskill targeted the external sibling chartazuremonitor-containerinsights-for-prod-clusters, which no longer reflects how CI/CD deploys the agent. This retargets it at the in-repocharts/azuremonitor-containerinsightsand corrects the mechanics that differ.Docs-only change — affects
.github/skills/backdoor-deployment/SKILL.mdonly. No product code or pipeline changes.What was broken
Four things would have caused a silent or hard failure if the skill were run against the in-repo chart as written:
Error: Chart.yaml file is missingenvsubstgeneration step, matching.pipelines/helm-deploy-templates/ama-logs-helm-deploy.yamlimageRepository+:+ tag, so the oldcidev:<tag>form renders the invalid.../ciprod:cidev:<tag>ciprod/cidevas a separateimageRepositoryvalue3.1.34inget.addonImageTag, so a run would compare prod against prod and report "no regression"<your_*>placeholders invalues-template.yamland cannot be parsed from the chart--setoverrides; workspace resolved from the DCRInput and discovery changes
ReleaseNotes.mdrather than a hardcoded tag that goes stale (the previous default,3.1.35, was already wrong).ContainerInsightsExtensionDCR →workspaceResourceId→customerId, with a bootstrap path that enables the addon once when no DCR exists yet. This matters because clusters onboarded without an explicit workspace land in a regional default such asDefaultWorkspace-<sub>-<region>, whose name is unrelated to the cluster.Deployment notes added
accessTokenSecretName=aad-msi-auth-token— MSI clusters need this in place of the chart's legacy workspace-key default.--server-side/--force-conflictsare Helm 4 flags (the pipeline pinshelmVersionToInstall: latest) and fail on Helm 3.Validation
Verified by an actual backdoor deployment to a test cluster, following the updated skill verbatim:
helm lintclean;helm templaterenders 9 objects with no unsubstituted placeholderskubectl apply --dry-run=servervalidated all 9 objects against a live K8s 1.34.4 API serveraad-msi-auth-tokenThe Helm ownership error and the DCR-deletion-on-disable behaviour documented here were both observed directly during this validation.